Techniques › T1040 › AN0878
AN0878 Analytic 0878
IaaS · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects creation of traffic mirroring sessions (e.g., AWS VPC Traffic Mirroring, Azure vTAP) that redirect traffic from critical assets to other virtual instances, often followed by file creation or session establishment.</p>
- Detects
- T1040 Network Sniffing
- Part of
- DET0314 Detection Strategy for Network Sniffing Across Platforms
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| AWS:CloudTrail | CreateTrafficMirrorSession / ModifyTrafficMirrorTarget | DC0069 Cloud Service Modification |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
MirrorSourceList | Identify VMs or containers where mirror sessions are abnormal or unexpected. |
TargetIAMRole | Monitor whether mirror target roles match administrative expectations. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2021-32030 | ASUS Routers | Mapped |
| CVE-2022-1040 | Sophos Firewall | Mapped |